Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-10622


Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from userspace in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8096AU, IPQ4019, IPQ6018, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, QCN7605, QCS605, SC8180X, SDM710, SDX24, SDX55, SM8150, SM8250, SXR2130


Published

2020-04-16T11:15:13.963

Last Modified

2024-11-21T04:19:36.477

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.1 (CRITICAL)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-125

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qualcomm apq8009_firmware - Yes
Hardware qualcomm apq8009 - No
Operating System qualcomm apq8096au_firmware - Yes
Hardware qualcomm apq8096au - No
Operating System qualcomm ipq4019_firmware - Yes
Hardware qualcomm ipq4019 - No
Operating System qualcomm ipq6018_firmware - Yes
Hardware qualcomm ipq6018 - No
Operating System qualcomm ipq8064_firmware - Yes
Hardware qualcomm ipq8064 - No
Operating System qualcomm ipq8074_firmware - Yes
Hardware qualcomm ipq8074 - No
Operating System qualcomm mdm9206_firmware - Yes
Hardware qualcomm mdm9206 - No
Operating System qualcomm mdm9207c_firmware - Yes
Hardware qualcomm mdm9207c - No
Operating System qualcomm mdm9607_firmware - Yes
Hardware qualcomm mdm9607 - No
Operating System qualcomm mdm9640_firmware - Yes
Hardware qualcomm mdm9640 - No
Operating System qualcomm mdm9650_firmware - Yes
Hardware qualcomm mdm9650 - No
Operating System qualcomm qcn7605_firmware - Yes
Hardware qualcomm qcn7605 - No
Operating System qualcomm qcs605_firmware - Yes
Hardware qualcomm qcs605 - No
Operating System qualcomm sc8180x_firmware - Yes
Hardware qualcomm sc8180x - No
Operating System qualcomm sdm710_firmware - Yes
Hardware qualcomm sdm710 - No
Operating System qualcomm sdx24_firmware - Yes
Hardware qualcomm sdx24 - No
Operating System qualcomm sdx55_firmware - Yes
Hardware qualcomm sdx55 - No
Operating System qualcomm sm8150_firmware - Yes
Hardware qualcomm sm8150 - No
Operating System qualcomm sm8250_firmware - Yes
Hardware qualcomm sm8250 - No
Operating System qualcomm sxr2130_firmware - Yes
Hardware qualcomm sxr2130 - No

References